Visualization of monitored data

Prev Next

OneSpan Threat View uses data on threat events received from your App Shielding integration and visualizes this data in different charts collected in widgets.

Threat View displays these widgets on the dashboard and in threat event reports in the Threat View Administration Interface. To access the Threat View Administration Interface, open http://localhost/adminui in an internet browser.

  • Dashboard

    The dashboard on the home page of the Threat View Administration Interface is a dynamic view on the collected data. It displays the widgets to provide an operational overview of recent data to facilitate taking decisions based on the threat landscape. For more information, see Dashboard.

  • Event-based investigation

    The All Events page enables you to to focus on events for your threat exposure investigation and visualize the results accordingly. For more information, see All Events: event-based investigation.

  • Threat event reports

    For authorized users, the dashboard displays the Threat Events Reports list. These reports, like the dashboard, also visualize the collected data in widgets but the report data can be filtered to focus on a specific time period. This enables a more in-depth analysis of the specified threat. Reports can only be accessed by authorized users with the corresponding permissions, typically Insights Viewer user accounts. For more information, see Threat event reports.

Charts and widgets

When collecting the data, Threat View uses different parameters to check against a given threat event and creates different types of widgets and charts to visualize the data. The following table provides an overview of the widget and chart types and the data analysis parameters used to create these.

Overview of analysis parameters and chart and widget types

Widget type:

chart type

Data analysis parameter

Session

Event

Location

Operating

System

Device

Model

Devices

Apps

Time

Period

Threat event

Users

Threat View Dashboard

Total numbers for previous day: big number charts

Events worldwide:

world map

N./A.

1

N./A.

1

Latest Events:

list (Dashboard)

N./A.

1

N./A.

1

Threat Events Reports:

list

N./A.

1

N./A.

1

All Events page

All Events: world map

N./A.

1

N./A.

1

All Events:

list

N./A.

1

N./A.

1

Threat View Reports

Total Events, Operating System Events: big number charts

Threat Event Trend: line chart

OS Usage: donut chart

Operating System Threat Event Trend: stacked areas charts

Top 10 Device Models: vertical bars chart

1: This distinction is only used in the Threat Event Reports.

Analysis parameters

The analysis parameters Threat View uses to check against a given threat event to create the charts are:

  • Total number of apps

  • Device model

  • Total number of devices

    Used only for the Total numbers for previous day widgets on the dashboard.

  • Session vs. Event

    • Sessions are the time span between starting the mobile app and shutting it down.

    • Events are the actual individual threat events.

  • Location

  • Operating system

  • Threat event

  • Time period

  • Total number of users

Chart types

The chart types with the aggregated data Threat View collects from Mobile Application Shielding to facilitate data consumption and analysis are:

  • World map

  • Lists

  • Big number charts

  • Line chart

  • Donut chart

  • Stacked area charts

  • Vertical bar chart

Widget types

On the dashboard, Threat View displays the following widget types:

  • Total numbers for previous day: big number charts

    Widgets with total numbers of a given set of analysis parameters for the previous day.

    • Events

    • Threat events

    • Users

    • Devices

    • Apps

  • Events worldwide: world map

    Correlated data aggregation: the total number of reported events during the last 7 days per country.

  • Latest Events: list

    List of all events based on a set of monitored data chosen for the list over a given period of time.

  • Threat Events Reports: list

    List with available threat event reports, analyzing the total number of threat events during the previous day.

On the All Events page, Threat View displays the following widget types:

  • World map with all events of the selected threat event type over the selected time period

  • List with all events, searchable by different parameters

In the individual threat reports, Threat View displays the following widget types:

  • Total Events, Operating system Events

    Big number charts with the total number of events and total number of events by operating system.

  • Threat event Trend

    Line chart for threat event by operating system. This widget shows the percentage of total sessions where a given threat event occurred per operating system for the selected time period per hour.

  • OS Usage

    Correlation of parameters. Donut chart with the distribution in percentage of a given threat event per operating system sessions for the selected time period.

  • Operating system threat event Trend

    Correlation of parameters. Stacked area charts with a comparison of the specific threat event and the total number of events per operating system for the selected time period.

  • Top 10 Device Models

    Vertical Bar Chart with the threat event, displaying events that occurred over the selected time period for the 10 device models with the most events of different threat events.

For more information on the widget types and the data they provide, see Dashboard, All Events, and Threat event reports.